nerdexam
Fortinet

NSE4 · Question #43

Review the configuration for FortiClient IPsec shown in the exhibit. Which statement is correct regarding this configuration?

The correct answer is A. The connecting VPN client will install a route to a destination corresponding to the. Based on the FortiClient IPsec configuration, the connecting VPN client will install a route specifically to the destination network(s) defined in the tunnel settings, indicating a split-tunneling setup.

Submitted by deeparc· Apr 18, 2026VPN and Routing

Question

Review the configuration for FortiClient IPsec shown in the exhibit. Which statement is correct regarding this configuration?

Exhibit

NSE4 question #43 exhibit

Options

  • AThe connecting VPN client will install a route to a destination corresponding to the
  • BThe connecting VPN client will install a default route.
  • CThe connecting VPN client will install a route to the 172.20.1.[1-5] address range.
  • DThe connecting VPN client will connect in web portal mode and no route will be installed.

How the community answered

(46 responses)
  • A
    80% (37)
  • B
    4% (2)
  • C
    13% (6)
  • D
    2% (1)

Why each option

Based on the FortiClient IPsec configuration, the connecting VPN client will install a route specifically to the destination network(s) defined in the tunnel settings, indicating a split-tunneling setup.

AThe connecting VPN client will install a route to a destination corresponding to theCorrect

A common FortiClient IPsec VPN configuration employs split tunneling, where the client is instructed to install specific routes only for the designated remote networks. This ensures that only traffic intended for the corporate network traverses the VPN tunnel, while other traffic (e.g., internet access) uses the local network connection directly.

BThe connecting VPN client will install a default route.

The client would install a default route only if configured for full tunneling, which sends all client traffic through the VPN, a different routing behavior than typically implied by specific destination routes.

CThe connecting VPN client will install a route to the 172.20.1.[1-5] address range.

While a route to a specific IP range might theoretically be possible, routing is typically configured for entire subnets (e.g., 172.20.1.0/24), not individual IP addresses or a small, non-standard range like 172.20.1.[1-5].

DThe connecting VPN client will connect in web portal mode and no route will be installed.

FortiClient IPsec establishes a Layer 3 tunnel that installs routes on the client, whereas web portal mode is characteristic of SSL VPNs, which often operate as application-layer proxies or require a separate client and do not typically install direct IPsec routes.

Concept tested: FortiClient IPsec routing (split tunneling)

Source: https://docs.fortinet.com/document/forticlient/7.0.7/administration-guide/523194/vpn-split-tunneling

Topics

#IPsec VPN#FortiClient#Split-tunneling#Client Routing

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice